- Description
- A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.
- Source
- patrick@puiterwijk.org
- NVD status
- Analyzed
- Products
- moodle
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- patrick@puiterwijk.org
- CWE-201
- Hype score
- Not currently trending
CVE-2025-67857 Moodle Anonymous Assignment Submission User ID Exposure Vulnerability https://t.co/wljUFoDGEq
@VulmonFeeds
3 Feb 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67857 A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewe… https://t.co/lLnYyMJ2bD
@CVEnew
3 Feb 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E22203C1-B84A-4B29-9F54-426C9F9DF046",
"versionEndExcluding": "4.1.21",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CED60CDC-8F12-481C-9ADD-8559860A2B3C",
"versionEndExcluding": "4.4.11",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C0CC5CF8-4808-41A5-B8A1-B0D6C575E5DC",
"versionEndExcluding": "4.5.8",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "06F81442-AEEB-483D-90A9-93DDBA5B95D6",
"versionEndExcluding": "5.0.4",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:5.1.0:-:*:*:*:*:*:*",
"matchCriteriaId": "567FEE12-0E75-4F0C-B22E-E76990C80E1B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]